2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18933 | — | — | 3.0% | Nov 5, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-18928 | — | — | 2.9% | Nov 4, 2018 | International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toSc... |
| CVE-2018-18927 | — | — | 0.6% | Nov 4, 2018 | An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typicall... |
| CVE-2018-18926 | — | — | 3.0% | Nov 4, 2018 | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to se... |
| CVE-2018-18925 | — | — | 31.9% | Nov 4, 2018 | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." s... |
| CVE-2018-18924 | — | — | 9.5% | Nov 4, 2018 | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file... |
| CVE-2018-18919 | — | — | 0.8% | Nov 4, 2018 | The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area. |
| CVE-2018-18909 | — | — | 0.9% | Nov 3, 2018 | xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code ... |
| CVE-2018-18903 | — | — | 5.2% | Nov 3, 2018 | Vanilla 2.6.x before 2.6.4 allows remote code execution. |
| CVE-2018-18915 | — | — | 1.8% | Nov 3, 2018 | There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted inpu... |
| CVE-2018-11062 | — | — | 1.8% | Nov 2, 2018 | Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin... |
| CVE-2018-7799 | — | — | 2.8% | Nov 2, 2018 | A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which c... |
| CVE-2018-17922 | — | — | 3.2% | Nov 2, 2018 | Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log f... |
| CVE-2018-17918 | — | — | 3.8% | Nov 2, 2018 | Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a... |
| CVE-2018-17912 | — | — | 1.6% | Nov 2, 2018 | An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow re... |
| CVE-2018-6909 | — | — | 1.1% | Nov 1, 2018 | A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web applic... |
| CVE-2018-6908 | — | — | 1.6% | Nov 1, 2018 | An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD ... |
| CVE-2018-6907 | — | — | 0.5% | Nov 1, 2018 | A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch... |
| CVE-2018-6906 | — | — | 0.7% | Nov 1, 2018 | A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and T... |
| CVE-2018-6012 | — | — | 1.3% | Nov 1, 2018 | The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject ... |
| CVE-2018-6011 | — | — | 1.1% | Nov 1, 2018 | The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2... |
| CVE-2018-18777 | — | — | 19.6% | Nov 1, 2018 | Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp... |
| CVE-2018-18776 | — | — | 2.3% | Nov 1, 2018 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (... |
| CVE-2018-18775 | — | — | 6.6% | Nov 1, 2018 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (... |
| CVE-2018-18714 | — | — | 0.9% | Nov 1, 2018 | RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now